Repository navigation
[security] Scope CI and release permissions to jobs that need them - #8637
Merged
Merged
Conversation
Validation: pre-commit checks passed. Generated with Codex
Keep read-only workflow defaults and grant OIDC access to the MSI build job, matching native Linux packaging. Retain contents read access for checkout. Validation: pre-commit checks passed. Generated with Codex
✅ All Policy Checks Passed
📖 Need help? See the Policy FAQ for details on every check and how to fix failures. |
|
🎉 All checks passed! This PR is ready for review. |
ScottTodd
marked this pull request as ready for review
September 30, 2026 21:27
ScottTodd
requested review from
arvindcheru,
nunnikri and
raramakr
as code owners
September 30, 2026 21:27
Member
Author
|
Relevant CI jobs have passed and I believe that the workflow code in rockrel (notably https://github.com/ROCm/rockrel/blob/main/.github/workflows/multi_arch_release.yml) is still compatible with these changes. Remaining CI jobs are queued on GPU test machines. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Sets minimal permissions across CI/CD workflow files to resolve https://docs.zizmor.sh/audits/#excessive-permissions findings.
Technical Details
id-token: writefrom workflow level to narrower job level where neededid-token: writefrom jobs that don't need it (e.g. no AWS credential setup for uploading files to S3)contents: readto jobs that specify permissions (these override the workflow default, checkout works for public repositories but private repositories reusing these workflows need the permission)Test Plan
Submission Checklist